Legal

Cookie policy

Last updated 7 September 2026 · Rabiʻ I 25, 1448 AH

Sections 6

This Cookie Policy explains the cookies and similar storage Azayemna uses on azayemna.com, and one thing that is not a cookie but that you should know about anyway. It is part of our Privacy Policy.

There is no separate cookie law in the UAE. Cookies are covered by the Personal Data Protection Law, Federal Decree-Law No. 45 of 2021 (PDPL), and only to the extent a cookie carries personal data. Article 4 of that law is what allows a cookie to be set without asking first, and only for the cases it lists. Everything else needs consent under Article 6, which has to be a clear positive action and has to be as easy to withdraw as it was to give.

This policy is published in Arabic and English. If the two versions ever differ, the Arabic version prevails.

The cookies we set

Every cookie below is needed to deliver the service you asked for, which is Article 4(9) of the PDPL. None of them is for advertising, and none of them follows you to another site.

Name What it does How long it lasts
azayemna_session Keeps a signed-in host or helper authenticated. Not readable by any script on the page. 15 minutes
azayemna_renew Renews the short session cookie without asking you to sign in again. Not readable by any script. 30 days
azayemna_here Says only that a session exists, so the page can show you as signed in before it asks the server. It holds no identity. 30 days
azayemna_stepup Records that an operator has re-authenticated, for the few actions that require it. Admin console only. 15 minutes
azayemna_visitor A random identifier for a person who is not signed in, written only when you like, save, or review a design. Nothing about you is in it. Reading a page never sets one. 12 months
azayemna_open A random number that tells one device from another at a connection, so the cap on a free invitation link can be counted. Set when you open an invitation link, and nothing else. Nothing about you is in it, nothing is read off your device to make it, and no script can read it. 12 months
azayemna_clear A signed note that this connection was checked and is not suspended, so we do not repeat the abuse check on every page. It holds no identity, only the moment it runs out, and no script can read it. 2 minutes

The visitor identifier is worth one more sentence, because it is one of the two that are not about signing in. It exists so that a design you liked stays liked, and so that a review you left stays yours to delete. It is written on the server, it is not readable by any script on the page, and it is never joined to your name, your email, or your phone number.

The device number is the other one, and the section below says what it is for.

Storage that is not a cookie

Some preferences are kept in your browser's own storage rather than in a cookie, which means they stay on your device and never reach us: whether you had the side panel wide or narrow, and, on a door helper's phone, the offline guest list for one event. That list is deleted the moment the scanner link for that event expires.

The cap on a free invitation link, and what counts it

Azayemna's free tier is one shareable invitation link, and that link stops opening once a set number of opens have been used. An open is worked out from two things: which connection a request arrived on, and which device at that connection it came from. The first five devices at one connection count as one open between them, and every two devices after that count as one more.

The connection comes from the network address every request carries, on our server, never from anything your browser tells us about itself. We never store the address. We store a keyed one-way fingerprint of it, which cannot be turned back into an address, and we delete it twelve months after that device last opened the link.

The device is the azayemna_open cookie in the table above. That is the one part of the cap that is storage on your machine, and it holds a random number and nothing else. Blocking it or clearing it does not lift the cap. It makes your browser look new to us the next time you open the link, which spends the host's allowance slightly faster rather than slower. No connection is ever counted for more than forty devices, so this cannot be used to close somebody's invitation.

The full explanation, including the legal basis and the rights you have, is in the Privacy Policy.

Payment pages

When you pay, the payment gateway loads its own secure form and may set its own cookies for fraud prevention, under its own policy rather than ours.

Consent, and managing cookies

We do not set an analytics cookie, an advertising cookie, or any cookie that follows you across sites. If that ever changes, we will ask you first through the consent notice, record your answer, and let you change it later. Under Article 6 of the PDPL that consent has to be a clear positive action, so nothing counts as consent because you scrolled past it.

You can clear or block cookies in your browser settings. Blocking the session cookies stops you from staying signed in. Blocking the visitor identifier means a like or a review you leave while signed out will not be recognised as yours afterwards. Blocking the device number changes nothing you can see: an invitation link still opens exactly as before.

Changes

We may update this policy as the product changes. The date above shows the latest version.

A question about this document?

Message us on WhatsApp. We answer in Arabic or English.